Getsymphony
Getsymphony Symphony: vulnerabilidades y CVE
Getsymphony Symphony tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-25912 | Crítica (9.1) | 1.4% | — | 31 oct 2021 | A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS). |
| CVE-2020-25343 | Media (5.4) | 0.71% | — | 7 oct 2020 | Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php |
| CVE-2020-15071 | Media (6.1) | 0.70% | — | 11 ago 2020 | content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading. |
| CVE-2018-12043 | Media (6.1) | 0.82% | — | 7 jun 2018 | content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page. |
| CVE-2017-8876 | Media (6.1) | 0.76% | — | 10 may 2017 | Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php. |
| CVE-2017-7694 | Alta (8.8) | 4.4% | — | 11 abr 2017 | Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be… |
| CVE-2017-6067 | Media (6.1) | 0.76% | — | 27 mar 2017 | Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field. |
| CVE-2017-5542 | Media (6.1) | 1.2% | — | 20 ene 2017 | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter. |
| CVE-2017-5541 | Media (5.3) | 2.5% | — | 20 ene 2017 | Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder… |
| CVE-2016-4309 | Alta (7.5) | 10% | — | 30 jun 2016 | Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter. |
| CVE-2015-8766 | Media (6.1) | 1.8% | — | 8 ene 2016 | Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1)… |
| CVE-2015-8376 | Media (6.1) | 0.95% | — | 8 ene 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to… |
| CVE-2015-4661 | Media (4.3) | 2.3% | — | 18 jun 2015 | Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort parameter to system/authors. |
| CVE-2013-7346 | Media (6.8) | 0.52% | — | 27 mar 2014 | Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the sort parameter… |
| CVE-2013-2559 | Media (6.5) | 2.4% | — | 27 mar 2014 | SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow… |
| CVE-2010-3458 | Alta (7.5) | 1.0% | — | 17 sept 2010 | SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some… |
| CVE-2010-3457 | Media (4.3) | 1.5% | — | 17 sept 2010 | Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in… |
| CVE-2010-2143 | Alta (7.5) | 7.3% | — | 3 jun 2010 | Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the mode parameter. |